How Has A Year Of Pandemic Changed Cyber Security?

In Association with AT Corp. 
In 2020 the pandemic hit and the world has been upside down ever since. So what have we learned during this time and how does it affect us moving forward? In one year the pandemic has transformed just about every part of our lives. From a technology perspective, advances that were “in progress”, like Telehealth, remote work, online retail. remote learning, distance education, virtual training - were thrown into hyper-drive. 
 
Office workers, front-line workers, and people in education, health care, hospitality, transportation and retail were quickly forced into new spaces where technology will have a big impact. Developments we thought were three to five years away are here now and those advances directly impact cyber security.

What Does That Mean To  Cyber Security Professionals?

The virus has impacted cyber in a major way. During the pandemic, “cyber criminals ditched many of their old tactics, placing a new emphasis on gathering intelligence, and exploiting and preying upon fears with targeted and sophisticated attacks.” 
There was “a notable shift in the devices targeted and strategies deployed by cyber criminals.” Though there is talk of a return to “normal,” it’s clear that many of the changes we’ve experienced in cybersecurity will become permanent.
 
The immediate impacts include real-world supply chains that are vulnerable to cyber attacks:  
 
  • Touchless commerce means QR codes are now the fastest growing threat vector, cyber attacks against managed service providers (MSPs) are growing, and attackers can compromise the software supply chain and modify executables). 
  • Social engineering can compromise social media platforms; bad actors turned health care records into best sellers. 
  • Cloud security misconfigurations are the leading cause of cloud data breaches, and we now know that Infrastructure monitoring is essential for identifying anomalies.
  • Telehealth means more online access for patients to the hospital IT systems. Hybrid schooling means more access to schools’ IT systems by educators and students. Remote work creates new vulnerabilities for businesses. 
Every industry is facing challenges due to adaptations made as a result of the pandemic. More technology means more consumers interacting with more devices and more suppliers interacting virtually with vendors. More interconnectedness. More entry points for cyber-attacks and more need to train, and retrain, your workforce, virtually most likely. “This past year has taught us that cyber criminals are increasingly formidable, planning long-term, strategic, and focused attacks that are sometimes years in the making. 2020 continued to show us that no company is immune, and there is no such thing as ‘safe enough,’” said Marcin Kleczynski, CEO of Malwarebytes.   

 

Here are some cyber security predictions for 2021 from Dan Lohrmann, CSO of Security Mentor, which have been ushered in by the changes in how we work due to the pandemic:  

  • There will be huge security impacts in the coming year from the move to work from home (WFH) fueled by COVID-19. More attacks will occur on home computers and networks, with bad actors even using home offices as criminal hubs by taking advantage of unpatched systems and architecture weaknesses.
  • The rush to cloud-everything will cause many security holes, challenges, misconfigurations and outages.
  • More growth in the security industry. Our numbers of new products and new year mergers and acquisitions will cause network complexity issues and integration problems and overwhelm cyber teams.
  • Privacy will be a mess, with user revolts, new laws, confusion and self-regulation failing.
  • Identity and multi-factor authentication (MFA) will take center stage as passwords (finally) start to go away in a tipping-point year.
  • Numerous high-profile Internet of Thing (IoT) hacks, some which will make headline news.
  • Ransomware will get worse and worse, with new twists, data stealing prior to encryption, malware packaging with other threats and very specific targeting of organisations.
  • Lots of 5G vulnerabilities will become headline news as the technology grows.
  • Advanced Persistent Threats (APT) attacks will be widely available from criminal networks. The dark web will allow criminals to buy access into more sensitive corporate networks.
  • Mobile devices, including smartphones, will be attacked in new ways, including app stores.
  • Crypto-currencies will play new roles, with criminals switching often for hiding advantages.
  • As digital transformation projects grow, many plans will implode as security challenges mount.

New Skills, New Training

As we rush into a new era, we create the need for new skills. New technology such as the Mobile Internet, Artificial Intelligence, Virtual and Augmented Reality, Cloud Technology, Internet of Things, Advanced Robotics, Biometric Technology, (think drop passwords and use voice, eye, hand, signature authentication), 3D Printing, Genomics, and Blockchain, creates the need for new skills, new training. 
 
Some experts predict there will be a skills shortage with lasting impacts from the pandemic generation, similar to those that marked Great Depression and World War II generations, with broad but hard-to-predict effects that will affect society for decades to come.
 
Companies and individuals must remain vigilant. And this involves making sure your cybersecurity force is as trained and as prepared as possible. 
 
More advances, more bad actors, and more vulnerabilities due to remote work forces and the Internet of Things demand that companies make every effort to upskill and reskill and retrain workers with real training. Leaders need to ensure that their workforce has the skills and training needed to adapt and thrive in this new environment. Michelle Parmelee Deputy CEO of Deloitte, said “If this year has taught us anything, it’s that learning—at school and at work—will never be the same. Already, it’s more digital and individualized, less fixed and face-to-face. And while it may be tempting to fight these changes and instead hope for a return to normalcy, the truth is that things were already trending this way.” 

Can CYRIN Training Help?  

In a word, Yes. One of the things we try to do at CYRIN is start to integrate people into the process. The process means always training and trying to stay up-to-date with your certifications but, most importantly, with your abilities. All the degrees and certifications don't mean anything if you can't do the job. What this pandemic has laid bare is the need for “re-skilling” or effective training. Very often organisations and their staff members receive theoretical knowledge and no practical skills at all. Theoretical knowledge has to be complemented by exercises that will help consolidate new skills.
 
For information on Cyrin cyber training > Click Here  <
 
AT Corp:       Fast Company:        Image: Unsplash
 
You Might Also Read: 
 
New Cyber Training For Security Professionals:
 
« In 2020 40% Of UK Businesses Suffered A Cyber Attack
China & India In Cyber Conflict »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

TrustedSec

TrustedSec

TrustedSec is an information security consulting services, providing tailored solutions and services for small, mid, and large businesses.

Centrify

Centrify

Centrify’s Next-Gen Access is an identity & access management solution that uniquely converges Identity-as-a-Service, enterprise mobility management and privileged access management.

SQA Service

SQA Service

SQA Service provide independent software and process Quality Assurance services.

ControlScan

ControlScan

ControlScan is a Managed Security Services Provider (MSSP) - our primary focus is protecting your business and securing your sensitive data.

Australian Cyber Security Growth Network (AustCyber)

Australian Cyber Security Growth Network (AustCyber)

AustCyber brings together businesses and researchers to develop the next generation of cyber security products and services.

Redjack

Redjack

Redjack is a cutting-edge network analytics company focused on enterprise and ISP security and intelligence solutions.

CyberPrism

CyberPrism

CyberPrism provides SaaS solutions using proprietary technology, underpinned by industry-leading technical practitioners to protect OT within Government, Maritime and Industrial markets.

Scanmeter

Scanmeter

Scanmeter helps identifying vulnerabilities in software and systems before they can be exploited by an attacker.

BlackCloak

BlackCloak

BlackCloak provides Concierge Cyber Security for high-net-worth individuals and corporate executives to protect them from cybercrime, reputational risks, hacking and identity theft.

Open Raven

Open Raven

Open Raven is the cloud native data security platform that prevents breaches driven by modern speed and sprawl. Restore full visibility and regain control within minutes, without agents.

BreachLock

BreachLock

Breachlock delivers the most comprehensive Penetration Testing as a Service (PtaaS) powered by Certified Hackers and AI.

Stripe OLT

Stripe OLT

At Stripe OLT, we provide complete business technology solutions - Our team has an unrivalled reputation as a Microsoft Gold Partner, specialising in secure, cloud-first technology.

Allentis

Allentis

Allentis provide adapted solutions to ensure the security and performance of your information system.

Tuta

Tuta

Tuta (formerly Tutanota) is an all-in-one email, calendar and contacts app which protects your data with full end-to-end encryption and it requires zero personal information.

Privasee

Privasee

Make GDPR compliance simple with Privasee. Our software makes it easy to protect your data and ensure you’re compliant with the new regulations.

Ronet Cyber Security

Ronet Cyber Security

Ronet Cyber Security offers crypto forensics services for regulators, law enforcement, companies and individuals to ensure that your transactions are safe and secure.

Cyberleaf

Cyberleaf

Cyberleaf is simplified managed cybersecurity for MSPs, enabling top tier cyber protection for small and medium enterprise.